Use permit! to allow arbitrary input from params

[ci skip]
pull/6827/head
Oliver Günther 7 years ago
parent f65e1e56d9
commit 79a7c8472a
No known key found for this signature in database
GPG Key ID: 88872239EB414F99
  1. 2
      lib/open_project/github_integration/hook_handler.rb

@ -30,7 +30,7 @@ module OpenProject::GithubIntegration
return 403 unless user.present?
payload = Hash.new
payload.merge! params.require('webhook')
payload.merge! params.require('webhook').permit!
payload.merge! 'user_id' => user.id,
'github_event' => event_type,
'github_delivery' => event_delivery

Loading…
Cancel
Save